Functionally Broken Institution
Guys who missed that their entire administration is now compromised by Russia lecture about security.
They are a laughing stock of intelligence community.
It's the biggest threat today, but it took her a while to appreciate it. After spending two decades at the FBI and much of that time working to intercept and stop cyber threats from the likes of China and Russia, Halcyon Ransomware Research Center SVP Cynthia Kaiser says she was a "latercomer to really wanting to focus on …
"can have disastrous, destructive impacts on business operations."
And that is necessarily a bad thing ?
By now if you haven't learnt, you never will. Arguably it would be a desirable outcome for all concerned if both you and your business were to disappear down the gurgler. Doubly so if you have been guzzling the AI lemonade and retrenched all your relevant staff.
"The Sicarii encryptor generates a new cryptographic key pair during every execution - but then discards the private key, "
That implies that asymmetric (public key) encryption is employed. Discarding the private key is legitimate as long as you retain the public key for decryption.
From a quick search it seems Sicarii used AES which is symmetric crypto (encryption and decryption use the same key) so deleting that key even accidentally by overwriting with new key material before recording the first key is a big oops.
I assume the idea is to generate a new AES key for each file and record the key and keyid in some sort of database and prepend a header containing the keyid and any salt (IV) to encrypted file. When done the key database is also encryped ... with some publlc key crypto and the private key is deleted with the public key retained by the villains to be later supplied to the victim for a fee (POA.)
Not exactly rocket surgery but this Russian group masquerading as Israelis (the unspeakable as the untouchable?) managed to cock it up in the simplest way possible.
"Discarding the private key is legitimate as long as you retain the public key for decryption."
That's not how public/private key encryption works. You can encrypt with the public something which you need the private to decrypt, but not the other way. What they were likely doing is encrypting each file symmetrically, encrypting that symmetric key with the public key, and then you could use the private key to recover the keys to decrypt. Except they deleted the private key so they can't do that. Generating a fresh keypair on the victim's computer is also stupid when you could just include the public key they're supposed to use.
Almost. Ransomware exists because getting cryptocurrency is legal. Stop the crypto, stop the ransomware.
No other form of money can flow so easily and anonymously across international boarders without restriction, such scams didn't exist before it, and wont exist after it.
"such scams didn't exist before it"
Complete rubbish. Money managed to cross borders, even illegally, before cryptocurrency. As long as paying it is still legal, criminals can come up with a different way to pay and companies can go along with that. Banning payments will be more successful and more obtainable than banning cryptocurrency.
If it wasn't crypto it'd be something else. That's just a tool.
Italy's kidnapping problem was almost wiped out by criminalising ransom payments (gangs were taking ransoms and killing the victim anyway, similar to what we're seeing with software ransoms)
I'm trying to figure out what useful information is surfaced in this article. You've got some mid-level FBI agent who was so ensconced in her little bubble that when she stepped outside, she was shocked that the sun was so bright. Reminds me of that joker Biden appointed who didn't realize cybersecurity was a major threat until 2019.
If someone is so stupid as to fail to understand someone so obvious and so unaware as to announce the fact, quietly just bury the interview. No need to further shame them by publicizing the interview.